<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HF not receiving logs from UF in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582892#M102705</link>
    <description>&lt;P&gt;It seems that you have tried configure both splunktcp and splunktcp-ssl on port 9997. Based on your app names etc. I suppose that splunktcp:9997 is winning listener. Then you probably try to send events from UF by splunktcp-ssl (port 9997 or 42000) and as 9997 is working with SSL it didn't accept your connection.&lt;/P&gt;&lt;P&gt;Please check from UF side which outputs.conf is in use and in which protocol and port it try to use.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jan 2022 09:16:50 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-01-28T09:16:50Z</dc:date>
    <item>
      <title>HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582177#M102567</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;&lt;P&gt;We have configured 3 new heavy forwarder in our splunk enterprise where 2 HF was already working.&lt;/P&gt;&lt;P&gt;Now we want traffic route from universal forwarder to&amp;nbsp; all the 5 HF but we are receiving traffic from only old 2 HF but not from 3 newly introduced HF.&lt;/P&gt;&lt;P&gt;telnet from UF to HF is working fine and input and output are configured properly.&lt;/P&gt;&lt;P&gt;Can any one suggest solution for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jan 2022 12:43:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582177#M102567</guid>
      <dc:creator>anil8</dc:creator>
      <dc:date>2022-01-23T12:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582178#M102568</link>
      <description>&lt;P&gt;Just missed to mentioned, I can see internal log from HF(new) to indexer. so, there is connectivity b/w HF to indexer.&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jan 2022 12:48:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582178#M102568</guid>
      <dc:creator>anil8</dc:creator>
      <dc:date>2022-01-23T12:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582180#M102569</link>
      <description>&lt;P&gt;2things to check for starters&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there input configured on hf to receive logs from uf&amp;nbsp;&lt;/P&gt;&lt;P&gt;And from uf are you getting anything on hf try netstat -aon |grep port on which you are forwarding.&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jan 2022 12:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582180#M102569</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-23T12:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582181#M102570</link>
      <description>&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Hello&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242416"&gt;@anil8&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Did you restarted UF&amp;nbsp; after updating the new HF list in outputs.conf&amp;nbsp; of UF? .&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;if Yes can you please run following command from Splunk bin directory on UF to check forwarders list&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;./splunk list forward-server&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;BR /&gt;o/p&lt;BR /&gt;Active forwards:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Configured but inactive forwards:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2. from Internal logs on UF did&amp;nbsp; you see nay WARN or ERROR messages for those new HFs configured&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jan 2022 12:58:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582181#M102570</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2022-01-23T12:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582203#M102576</link>
      <description>&lt;P&gt;Have you updated your outputs.conf on UFs to use also these 3 new HFs and restart those after that?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 07:20:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582203#M102576</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-24T07:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582206#M102578</link>
      <description>&lt;P&gt;yes, We have updated&amp;nbsp;&lt;SPAN&gt;outputs.conf&amp;nbsp;for for 3 new HF&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 07:23:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582206#M102578</guid>
      <dc:creator>anil8</dc:creator>
      <dc:date>2022-01-24T07:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582710#M102659</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236694"&gt;@SanjayReddy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;I am getting below error in Splunkd log in in HF.&lt;/P&gt;&lt;P&gt;01-27-2022 09:41:18.678 +0000 ERROR TcpInputProc [17904 FwdDataReceiverThread] - Message rejected. Received unexpected message of size=369295616 bytes from src=XXXX(UF) in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and below one is from UF:&lt;/P&gt;&lt;P&gt;01-27-2022 09:52:47.004 +0000 WARN TcpOutputFd - Connect to XXXX:9997(HF failed. Connection refused&lt;BR /&gt;01-27-2022 09:52:47.004 +0000 ERROR TcpOutputFd - Connection to host=XXXX:9997(HF) failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 09:57:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582710#M102659</guid>
      <dc:creator>anil8</dc:creator>
      <dc:date>2022-01-27T09:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582769#M102680</link>
      <description>&lt;P&gt;can you paste the inputs.conf from hf after removing sensitive data.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 15:03:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582769#M102680</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-27T15:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582773#M102682</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228600"&gt;@SinghK&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;Please find the below inputs.conf in system/default and system/local.&lt;/P&gt;&lt;P&gt;Please free to ask any other details.&lt;/P&gt;&lt;P&gt;[default]$ SplunkHome/etc/system/default&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;# Version 8.2.0&lt;BR /&gt;# DO NOT EDIT THIS FILE!&lt;BR /&gt;# Changes to default files will be lost on update and are difficult to&lt;BR /&gt;# manage and support.&lt;BR /&gt;#&lt;BR /&gt;# Please make any changes to system defaults by overriding them in&lt;BR /&gt;# apps or $SPLUNK_HOME/etc/system/local&lt;BR /&gt;# (See "Configuration file precedence" in the web documentation).&lt;BR /&gt;#&lt;BR /&gt;# To override a specific setting, copy the name of the stanza and&lt;BR /&gt;# setting to the file where you wish to override it.&lt;BR /&gt;#&lt;BR /&gt;# This file contains possible attributes and values you can use to&lt;BR /&gt;# configure inputs, distributed inputs and file system monitoring.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[default]&lt;BR /&gt;index = default&lt;BR /&gt;_rcvbuf = 1572864&lt;BR /&gt;host = $decideOnStartup&lt;/P&gt;&lt;P&gt;[blacklist:$SPLUNK_HOME/etc/auth]&lt;/P&gt;&lt;P&gt;[blacklist:$SPLUNK_HOME/etc/passwd]&lt;/P&gt;&lt;P&gt;[monitor://$SPLUNK_HOME/var/log/splunk]&lt;BR /&gt;index = _internal&lt;/P&gt;&lt;P&gt;[monitor://$SPLUNK_HOME/var/log/watchdog/watchdog.log*]&lt;BR /&gt;index = _internal&lt;/P&gt;&lt;P&gt;[monitor://$SPLUNK_HOME/var/log/splunk/license_usage_summary.log]&lt;BR /&gt;index = _telemetry&lt;/P&gt;&lt;P&gt;[monitor://$SPLUNK_HOME/var/log/splunk/splunk_instrumentation_cloud.log*]&lt;BR /&gt;index = _telemetry&lt;BR /&gt;sourcetype = splunk_cloud_telemetry&lt;/P&gt;&lt;P&gt;[monitor://$SPLUNK_HOME/etc/splunk.version]&lt;BR /&gt;_TCP_ROUTING = *&lt;BR /&gt;index = _internal&lt;BR /&gt;sourcetype=splunk_version&lt;/P&gt;&lt;P&gt;[batch://$SPLUNK_HOME/var/run/splunk/search_telemetry/*search_telemetry.json]&lt;BR /&gt;move_policy = sinkhole&lt;BR /&gt;index = _introspection&lt;BR /&gt;sourcetype = search_telemetry&lt;BR /&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;log_on_completion = 0&lt;/P&gt;&lt;P&gt;[batch://$SPLUNK_HOME/var/spool/splunk]&lt;BR /&gt;move_policy = sinkhole&lt;BR /&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;[batch://$SPLUNK_HOME/var/spool/splunk/tracker.log*]&lt;BR /&gt;index = _internal&lt;BR /&gt;sourcetype = splunkd_latency_tracker&lt;BR /&gt;move_policy = sinkhole&lt;/P&gt;&lt;P&gt;[batch://$SPLUNK_HOME/var/spool/splunk/...stash_new]&lt;BR /&gt;queue = stashparsing&lt;BR /&gt;sourcetype = stash_new&lt;BR /&gt;move_policy = sinkhole&lt;BR /&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;time_before_close = 0&lt;/P&gt;&lt;P&gt;[batch://$SPLUNK_HOME/var/spool/splunk/...stash_hec]&lt;BR /&gt;sourcetype = stash_hec&lt;BR /&gt;move_policy = sinkhole&lt;BR /&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;[fschange:$SPLUNK_HOME/etc]&lt;BR /&gt;disabled = false&lt;BR /&gt;#poll every 10 minutes&lt;BR /&gt;pollPeriod = 600&lt;BR /&gt;#generate audit events into the audit index, instead of fschange events&lt;BR /&gt;signedaudit=true&lt;BR /&gt;recurse=true&lt;BR /&gt;followLinks=false&lt;BR /&gt;hashMaxSize=-1&lt;BR /&gt;fullEvent=false&lt;BR /&gt;sendEventMaxSize=-1&lt;BR /&gt;filesPerDelay = 10&lt;BR /&gt;delayInMills = 100&lt;/P&gt;&lt;P&gt;[udp]&lt;BR /&gt;connection_host=ip&lt;/P&gt;&lt;P&gt;[tcp]&lt;BR /&gt;acceptFrom=*&lt;BR /&gt;connection_host=dns&lt;/P&gt;&lt;P&gt;[splunktcp]&lt;BR /&gt;route=has_key:_replicationBucketUUID:replicationQueue;has_key:_dstrx:typingQueue;has_key:_linebreaker:indexQueue;absent_key:_linebreaker:parsingQueue&lt;BR /&gt;acceptFrom=*&lt;BR /&gt;connection_host=ip&lt;/P&gt;&lt;P&gt;[script]&lt;BR /&gt;interval = 60.0&lt;BR /&gt;start_by_shell = true&lt;/P&gt;&lt;P&gt;[SSL]&lt;BR /&gt;# SSL settings&lt;BR /&gt;# The following provides modern TLS configuration that guarantees forward-&lt;BR /&gt;# secrecy and efficiency. This configuration drops support for old Splunk&lt;BR /&gt;# versions (Splunk 5.x and earlier).&lt;BR /&gt;# To add support for Splunk 5.x set sslVersions to tls and add this to the&lt;BR /&gt;# end of cipherSuite:&lt;BR /&gt;# DHE-RSA-AES256-SHA:AES256-SHA:DHE-RSA-AES128-SHA:AES128-SHA&lt;BR /&gt;# and this, in case Diffie Hellman is not configured:&lt;BR /&gt;# AES256-SHA:AES128-SHA&lt;/P&gt;&lt;P&gt;sslVersions = tls1.2&lt;BR /&gt;cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256&lt;BR /&gt;ecdhCurves = prime256v1, secp384r1, secp521r1&lt;/P&gt;&lt;P&gt;allowSslRenegotiation = true&lt;BR /&gt;sslQuietShutdown = false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$ /opt/ee_splunk/splunk/etc/system/local&lt;/P&gt;&lt;P&gt;[monitor:///tmp/test]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 15:20:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582773#M102682</guid>
      <dc:creator>anil8</dc:creator>
      <dc:date>2022-01-27T15:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582776#M102684</link>
      <description>&lt;P&gt;Ah there is no input defined to receive logs from UF.&lt;/P&gt;&lt;P&gt;[splunktcp://&amp;lt;port you are connecting with hf from uf .] e.g. [splunktcp://:9997]&lt;/P&gt;&lt;P&gt;index= &amp;lt;your index&amp;gt;&lt;/P&gt;&lt;P&gt;disabled =0&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and add that line to at bottom of file or in local directory create a inpust.conf and put the info there and restart splunk service.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 15:29:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582776#M102684</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-27T15:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582792#M102691</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228600"&gt;@SinghK&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I added the below in local inputs.conf but still i am getting the same error. 9997 is the port on which UF is sending the logs&lt;/P&gt;&lt;P&gt;[splunktcp://:9997]&lt;BR /&gt;index = test&lt;BR /&gt;disabled = 0&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 16:48:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582792#M102691</guid>
      <dc:creator>anil8</dc:creator>
      <dc:date>2022-01-27T16:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582793#M102692</link>
      <description>&lt;P&gt;Can you please list the output of this command&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk_home/bin/splunk btool inputs list --debug&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 16:53:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582793#M102692</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-27T16:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582887#M102703</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228600"&gt;@SinghK&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Please find the output of&amp;nbsp;Splunk_home/bin/splunk btool inputs list --debug below&lt;/P&gt;&lt;P&gt;Kindly let me know if any other information required.&lt;/P&gt;&lt;P&gt;[splunk@XXXX bin]$ ./splunk btool inputs list --debug&lt;BR /&gt;SPLUNK_HOME/apps/splunk_UF_HF_custom_ssl/local/inputs.conf [SSL]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf allowSslRenegotiation = true&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf ecdhCurves = prime256v1, secp384r1, secp521r1&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_UF_HF_custom_ssl/local/inputs.conf requireClientCert = false&lt;BR /&gt;SPLUNK_HOME/apps/splunk_UF_HF_custom_ssl/local/inputs.conf serverCert = SPLUNK_HOME/apps/splunk_UF_HF_certificates/auth/HFServerCertificate.pem&lt;BR /&gt;SPLUNK_HOME/apps/splunk_UF_HF_custom_ssl/local/inputs.conf sslPassword = $7$3z35Ihr9fi8UGaqQIwH/hRBJRYUhe6Icor3Ajha+rVovWHLQplcosqLi&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf sslQuietShutdown = false&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf sslVersions = tls1.2&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [batch:///opt/ee_splunk/splunk/var/run/splunk/search_telemetry/*search_telemetry.json]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = _introspection&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf log_on_completion = 0&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf move_policy = sinkhole&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf sourcetype = search_telemetry&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [batch:///opt/ee_splunk/splunk/var/spool/splunk]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf move_policy = sinkhole&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [batch:///opt/ee_splunk/splunk/var/spool/splunk/...stash_hec]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf move_policy = sinkhole&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf sourcetype = stash_hec&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [batch:///opt/ee_splunk/splunk/var/spool/splunk/...stash_new]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf move_policy = sinkhole&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf queue = stashparsing&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf sourcetype = stash_new&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf time_before_close = 0&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [batch:///opt/ee_splunk/splunk/var/spool/splunk/tracker.log*]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = _internal&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf move_policy = sinkhole&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf sourcetype = splunkd_latency_tracker&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [blacklist:SPLUNK_HOME/auth]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [blacklist:SPLUNK_HOME/passwd]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [fschange:SPLUNK_HOME]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf delayInMills = 100&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf disabled = false&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf filesPerDelay = 10&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf followLinks = false&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf fullEvent = false&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf hashMaxSize = -1&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf pollPeriod = 600&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf recurse = true&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf sendEventMaxSize = -1&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf signedaudit = true&lt;BR /&gt;SPLUNK_HOME/apps/splunk_httpinput/default/inputs.conf [http]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/apps/splunk_httpinput/default/inputs.conf ackIdleCleanup = true&lt;BR /&gt;SPLUNK_HOME/apps/splunk_httpinput/default/inputs.conf allowSslCompression = true&lt;BR /&gt;SPLUNK_HOME/apps/splunk_httpinput/default/inputs.conf allowSslRenegotiation = true&lt;BR /&gt;SPLUNK_HOME/apps/splunk_httpinput/default/inputs.conf dedicatedIoThreads = 2&lt;BR /&gt;SPLUNK_HOME/apps/splunk_httpinput/default/inputs.conf disabled = 1&lt;BR /&gt;SPLUNK_HOME/apps/splunk_httpinput/default/inputs.conf enableSSL = 1&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_httpinput/default/inputs.conf maxSockets = 0&lt;BR /&gt;SPLUNK_HOME/apps/splunk_httpinput/default/inputs.conf maxThreads = 0&lt;BR /&gt;SPLUNK_HOME/apps/splunk_httpinput/default/inputs.conf port = 8088&lt;BR /&gt;SPLUNK_HOME/apps/splunk_httpinput/default/inputs.conf sslVersions = *,-ssl2&lt;BR /&gt;SPLUNK_HOME/apps/splunk_httpinput/default/inputs.conf useDeploymentServer = 0&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [monitor://SPLUNK_HOME/splunk.version]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _TCP_ROUTING = *&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = _internal&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf sourcetype = splunk_version&lt;BR /&gt;SPLUNK_HOME/apps/introspection_generator_addon/default/inputs.conf [monitor:///opt/ee_splunk/splunk/var/log/introspection]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/apps/introspection_generator_addon/default/inputs.conf index = _introspection&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [monitor:///opt/ee_splunk/splunk/var/log/splunk]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = _internal&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [monitor:///opt/ee_splunk/splunk/var/log/splunk/license_usage_summary.log]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = _telemetry&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [monitor:///opt/ee_splunk/splunk/var/log/splunk/splunk_instrumentation_cloud.log*]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = _telemetry&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf sourcetype = splunk_cloud_telemetry&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [monitor:///opt/ee_splunk/splunk/var/log/watchdog/watchdog.log*]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = _internal&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [script]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf interval = 60.0&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf start_by_shell = true&lt;BR /&gt;SPLUNK_HOME/apps/introspection_generator_addon/default/inputs.conf [script://SPLUNK_HOME/apps/introspection_generator_addon/bin/collector.path]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/introspection_generator_addon/default/inputs.conf interval = 0&lt;BR /&gt;SPLUNK_HOME/apps/introspection_generator_addon/default/inputs.conf sourcetype = splunk_resource_usage__internal&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf [script://SPLUNK_HOME/apps/python_upgrade_readiness_app/bin/pura_get_all_apps.py]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf disabled = 0&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf interval = 00 23 */1 * *&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf passAuth = admin&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf sourcetype = script&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf [script://SPLUNK_HOME/apps/python_upgrade_readiness_app/bin/pura_scan_apps.py]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf disabled = 0&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf interval = 00 1 */1 * *&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf passAuth = admin&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf sourcetype = script&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf [script://SPLUNK_HOME/apps/python_upgrade_readiness_app/bin/pura_send_email.py]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf disabled = 0&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf interval = 0 6 * * 1&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf passAuth = admin&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/python_upgrade_readiness_app/default/inputs.conf sourcetype = script&lt;BR /&gt;SPLUNK_HOME/apps/splunk-dashboard-studio/default/inputs.conf [script://SPLUNK_HOME/apps/splunk-dashboard-studio/bin/save_image_and_icon_on_install.py]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk-dashboard-studio/default/inputs.conf interval = -1&lt;BR /&gt;SPLUNK_HOME/apps/splunk-dashboard-studio/default/inputs.conf passAuth = splunk-system-user&lt;BR /&gt;SPLUNK_HOME/apps/splunk-dashboard-studio/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk-dashboard-studio/default/inputs.conf run_only_one = false&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf [script://SPLUNK_HOME/apps/splunk_instrumentation/bin/instrumentation.py]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf disabled = false&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf index = _telemetry&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf interval = 0 * * * *&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf passAuth = splunk-system-user&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf source = instrumentation_scripted_input&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf sourcetype = splunk_telemetry_log&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf [script://SPLUNK_HOME/apps/splunk_instrumentation/bin/on_splunk_start.py]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf disabled = false&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf interval = -1&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf passAuth = splunk-system-user&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf [script://SPLUNK_HOME/apps/splunk_instrumentation/bin/schedule_delete.py]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf disabled = false&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf interval = 0 0 * * *&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf passAuth = splunk-system-user&lt;BR /&gt;SPLUNK_HOME/apps/splunk_instrumentation/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk_monitoring_console/default/inputs.conf [script://SPLUNK_HOME/apps/splunk_monitoring_console/bin/dmc_config.py]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_monitoring_console/default/inputs.conf interval = -1&lt;BR /&gt;SPLUNK_HOME/apps/splunk_monitoring_console/default/inputs.conf passAuth = splunk-system-user&lt;BR /&gt;SPLUNK_HOME/apps/splunk_monitoring_console/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf [secure_gateway_modular_input://default]&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf disabled = 1&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 09:06:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582887#M102703</guid>
      <dc:creator>anil8</dc:creator>
      <dc:date>2022-01-28T09:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582889#M102704</link>
      <description>&lt;P&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf [secure_gateway_modular_input://default]&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf disabled = 1&lt;BR /&gt;host = $decideOnStartup&lt;BR /&gt;index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf interval = 1&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [splunktcp]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf acceptFrom = *&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf connection_host = ip&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf route = has_key:_replicationBucketUUID:replicationQueue;has_key:_dstrx:typingQueue;has_key:_linebreaker:indexQueue;absent_key:_linebreaker:parsingQueue&lt;BR /&gt;SPLUNK_HOME/apps/splunk_UF_HF_custom_ssl/local/inputs.conf [splunktcp-ssl://42000]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_UF_HF_custom_ssl/local/inputs.conf [splunktcp-ssl://9997]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/launcher/local/inputs.conf [splunktcp://42000]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/apps/launcher/local/inputs.conf connection_host = ip&lt;BR /&gt;SPLUNK_HOME/apps/launcher/local/inputs.conf disabled = 0&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/launcher/local/inputs.conf [splunktcp://9997]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/apps/launcher/local/inputs.conf connection_host = ip&lt;BR /&gt;SPLUNK_HOME/apps/launcher/local/inputs.conf disabled = 0&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/system/local/inputs.conf [splunktcp://:9997]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/local/inputs.conf disabled = 0&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/local/inputs.conf index = test&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf [ssg_alerts_ttl_modular_input://default]&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf disabled = 1&lt;BR /&gt;host = $decideOnStartup&lt;BR /&gt;index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf interval = 3600&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf ttl_days = 1&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf [ssg_delete_tokens_modular_input://default]&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf disabled = 1&lt;BR /&gt;host = $decideOnStartup&lt;BR /&gt;index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf interval = 7200&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf [ssg_device_role_modular_input://default]&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf disabled = 1&lt;BR /&gt;host = $decideOnStartup&lt;BR /&gt;index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf interval = 300&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf [ssg_enable_modular_input://default]&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf disabled = 0&lt;BR /&gt;host = $decideOnStartup&lt;BR /&gt;index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf interval = 60&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf [ssg_metrics_modular_input://default]&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf disabled = 1&lt;BR /&gt;host = $decideOnStartup&lt;BR /&gt;index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf interval = 43200&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf [ssg_registered_users_list_modular_input://default]&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf disabled = 1&lt;BR /&gt;host = $decideOnStartup&lt;BR /&gt;index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf interval = 86400&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf [ssg_subscription_clean_up_modular_input://default]&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf cleanup_threshold_seconds = 120&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf disabled = 1&lt;BR /&gt;host = $decideOnStartup&lt;BR /&gt;index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf interval = 120&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf [ssg_subscription_modular_input://default]&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf disabled = 1&lt;BR /&gt;host = $decideOnStartup&lt;BR /&gt;index = default&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf interval = 0&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf maximum_iteration_time_warn_threshold_seconds = 300&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf minimum_iteration_time_seconds = 5&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf python.version = python3&lt;BR /&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf subscription_processor_parallelism = N_CPU&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [tcp]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf acceptFrom = *&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf connection_host = dns&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf [udp]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf connection_host = ip&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;BR /&gt;SPLUNK_HOME/apps/btec_t_input_apigw_op/default/inputs.conf [udp://10714]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/apps/btec_t_input_apigw_op/default/inputs.conf acceptFrom = 10.50.146.148,10.50.146.149,10.50.146.150,10.50.146.151,10.36.85.77,10.36.85.78,10.36.85.79,10.36.85.80&lt;BR /&gt;SPLUNK_HOME/apps/btec_t_input_apigw_op/default/inputs.conf disabled = false&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/apps/btec_t_input_apigw_op/default/inputs.conf index = rt_apigw&lt;BR /&gt;SPLUNK_HOME/apps/btec_t_input_apigw_op/default/inputs.conf sourcetype = syslog&lt;BR /&gt;SPLUNK_HOME/apps/btec_p_input_excalibur/default/inputs.conf [udp://10715]&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;SPLUNK_HOME/apps/btec_p_input_excalibur/default/inputs.conf acceptFrom = 10.45.26.137,10.45.26.138,10.45.26.139,10.45.26.140,10.45.9.15,10.45.52.227,10.45.52.228&lt;BR /&gt;SPLUNK_HOME/apps/btec_p_input_excalibur/default/inputs.conf disabled = false&lt;BR /&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;SPLUNK_HOME/apps/btec_p_input_excalibur/default/inputs.conf index = rt_excalibur&lt;BR /&gt;SPLUNK_HOME/apps/btec_p_input_excalibur/default/inputs.conf sourcetype = excalibur_LB&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 09:05:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582889#M102704</guid>
      <dc:creator>anil8</dc:creator>
      <dc:date>2022-01-28T09:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582892#M102705</link>
      <description>&lt;P&gt;It seems that you have tried configure both splunktcp and splunktcp-ssl on port 9997. Based on your app names etc. I suppose that splunktcp:9997 is winning listener. Then you probably try to send events from UF by splunktcp-ssl (port 9997 or 42000) and as 9997 is working with SSL it didn't accept your connection.&lt;/P&gt;&lt;P&gt;Please check from UF side which outputs.conf is in use and in which protocol and port it try to use.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 09:16:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582892#M102705</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-28T09:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582893#M102706</link>
      <description>&lt;P&gt;you have duplicate inputs configured on same port&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SPLUNK_HOME/apps/splunk_UF_HF_custom_ssl/local/inputs.conf [splunktcp-ssl://42000]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/apps/splunk_UF_HF_custom_ssl/local/inputs.conf [splunktcp-ssl://9997]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/apps/launcher/local/inputs.conf [splunktcp://42000]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/apps/launcher/local/inputs.conf connection_host = ip&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/apps/launcher/local/inputs.conf disabled = 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/apps/launcher/local/inputs.conf [splunktcp://9997]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/apps/launcher/local/inputs.conf connection_host = ip&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/apps/launcher/local/inputs.conf disabled = 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf index = default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/local/inputs.conf [splunktcp://:9997]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf _rcvbuf = 1572864&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/local/inputs.conf disabled = 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/default/inputs.conf host = $decideOnStartup&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/system/local/inputs.conf index = test&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SPLUNK_HOME/apps/splunk_secure_gateway/default/inputs.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;do you have ssl enabled in your environment ? as i can see you have some ssl inputs configured.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if the answer to this is yes have created ssl certs for new hf's ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 09:17:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582893#M102706</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-28T09:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582899#M102708</link>
      <description>&lt;P&gt;Yes...I have created the SSL certificate.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 09:42:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582899#M102708</guid>
      <dc:creator>anil8</dc:creator>
      <dc:date>2022-01-28T09:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582901#M102709</link>
      <description>&lt;P&gt;Please paste the outputs.conf from uf&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 09:53:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582901#M102709</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-28T09:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582905#M102710</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228600"&gt;@SinghK&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find below output.conf from UF&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;defaultGroup = splunkssl&lt;BR /&gt;useACK = true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[tcpout:splunkssl]&lt;BR /&gt;server = XXXX.XX.XX.com:9997,XXXX.XX.XX.com:9997,XXXX.XX.XX.com:9997,XXXX.XX.XX.com:9997,XXXX.XX.XX.com:9997&lt;BR /&gt;sslCertPath = /opt/product/splunk/splunkforwarder_ee/etc/apps/ee_splunk_forwarder_certs/auth/Forwarder.pem&lt;BR /&gt;sslPassword = ee_splunk_iif&lt;BR /&gt;sslRootCAPath = /opt/product/splunk/splunkforwarder_ee/etc/apps/ee_splunk_forwarder_certs/auth/UFHFCACertificate.pem&lt;BR /&gt;sslVerifyServerCert = false&lt;BR /&gt;useSSL=true&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 10:02:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582905#M102710</guid>
      <dc:creator>anil8</dc:creator>
      <dc:date>2022-01-28T10:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: HF not receiving logs from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582906#M102711</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please advice what change should be done in output.conf in UF.&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;defaultGroup = splunkssl&lt;BR /&gt;useACK = true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[tcpout:splunkssl]&lt;BR /&gt;server = XXXX.XX.XX.com:9997,XXXX.XX.XX.com:9997,XXXX.XX.XX.com:9997,XXXX.XX.XX.com:9997,XXXX.XX.XX.com:9997&lt;BR /&gt;sslCertPath = /opt/product/splunk/splunkforwarder_ee/etc/apps/ee_splunk_forwarder_certs/auth/Forwarder.pem&lt;BR /&gt;sslPassword = ee_splunk_iif&lt;BR /&gt;sslRootCAPath = /opt/product/splunk/splunkforwarder_ee/etc/apps/ee_splunk_forwarder_certs/auth/UFHFCACertificate.pem&lt;BR /&gt;sslVerifyServerCert = false&lt;BR /&gt;useSSL=true&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 10:12:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-not-receiving-logs-from-UF/m-p/582906#M102711</guid>
      <dc:creator>anil8</dc:creator>
      <dc:date>2022-01-28T10:12:23Z</dc:date>
    </item>
  </channel>
</rss>

